TO BEnchmark or NOT TO BEnchmark security: That is the question

The multiplicity of available software and component alternatives has boosted the interest in suitable benchmarks, able to assist in the selection of candidate solutions from the existing diversity, concerning several attributes. The huge success of performance and dependability benchmarking, however, markedly contrasts with the small advances on security benchmarking, which has only sparsely been studied in recent years. In this position paper we discuss the difficulties involved in applying the dependability benchmarking approach to the security context, and propose and discuss an appealing alternative: trustworthiness benchmarking.